<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some LDAP Users cannot login in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35388#M14931</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, as Axel mentioned, log4j is your friend. Maybe this logger also helps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;log4j.logger.org.alfresco.repo.security.authentication.ldap=DEBUG&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, is this for an OpenLDAP or for an Active Directory ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S: By the way, you can set ldap.authentication.allowGuestLogin=false&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Aug 2017 10:03:10 GMT</pubDate>
    <dc:creator>cesarista</dc:creator>
    <dc:date>2017-08-07T10:03:10Z</dc:date>
    <item>
      <title>Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35386#M14929</link>
      <description>Hello,I am currently working with Alfresco Community 5.2f and I have a problem with our LDAP authentication configuration. Mostly everyday there is an user who cannot login and nothing is in the logfile. The user is not locked in AD, because he can login in other applications and the other users can</description>
      <pubDate>Mon, 07 Aug 2017 08:35:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35386#M14929</guid>
      <dc:creator>t_schoeberl</dc:creator>
      <dc:date>2017-08-07T08:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35387#M14930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there is currently nothing in the log file then it is a bit&amp;nbsp;difficult to guess what might be the cause, especially since other users can login. I recommend adjusting the log levels to get more information.Though Alfresco can be annoyingly reserved when it comes to logging, there might be some info to be gained. The following logger(s) should be set to DEBUG:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;org.alfresco.repo.security.sync.ldap.LDAPUserRegistry&lt;/LI&gt;&lt;LI&gt;org.springframework.extensions.webscripts.DeclarativeWebScript&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since these loggers can create quite a lot of output it is recommended to only have them active when reproducing this issue with an end user. Normally, Alfresco Community Edition does not support dynamic changes to Log4J configuration, but you could use the &lt;A href="https://github.com/OrderOfTheBee/ootbee-support-tools" rel="nofollow noopener noreferrer"&gt;OOTBee Support Tools&lt;/A&gt; addon which adds this capability to the Repository Administration Console / Share Admin Tools.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DeclarativeWebScript is&amp;nbsp;the generic class for all web scripts - setting its logger is meant to have Alfresco log out the error message for&amp;nbsp;the authentication via the Share login form. The LDAPUserRegistry is used in parts of the authentication exchange when the user DN needs to be resolved from a simplified user name (in your case, matching the user name input against the CN of users).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 09:37:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35387#M14930</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-08-07T09:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35388#M14931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, as Axel mentioned, log4j is your friend. Maybe this logger also helps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;log4j.logger.org.alfresco.repo.security.authentication.ldap=DEBUG&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, is this for an OpenLDAP or for an Active Directory ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S: By the way, you can set ldap.authentication.allowGuestLogin=false&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 10:03:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35388#M14931</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-08-07T10:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35389#M14932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes like you mentioned, I didn't want to set the loglevel to debug, because the output is quite a lot. Thanks, i will try the OOTBee Support Tools addon. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="80296" __jive_macro_name="user" _jive_internal="true" data-id="80296" data-objecttype="3" data-type="person" href="https://community.alfresco.com/people/cesarista" rel="nofollow noopener noreferrer"&gt;&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;Its for an Active Directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 10:10:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35389#M14932</guid>
      <dc:creator>t_schoeberl</dc:creator>
      <dc:date>2017-08-07T10:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35390#M14933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So i installed the OOTBee Support Tools and set the LogLevel to DEBUG. If a user log in to Alfresco I see a DEBUG output in the Logfile. But unfortunately if a user who is locked try to log in, I see nothing in the logfile and he cannot log in. We think that the user is locked in AD and after 30 minutes he is unlocked but Alfresco don't recognize this and don't authenticate aigainst AD. Is the user locked somewhere in Alfresco intern? Do you have any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Aug 2017 06:52:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35390#M14933</guid>
      <dc:creator>t_schoeberl</dc:creator>
      <dc:date>2017-08-08T06:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35391#M14934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tanja:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm asking because there exists&amp;nbsp;two different OOTB&amp;nbsp;subsystems for Alfresco: ldap (for OpenLDAP) and ldap-ad (for Active Directory using LDAP&amp;nbsp;protocol).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://github.com/Alfresco/community-edition-old/blob/master/projects/repository/config/alfresco/subsystems/Authentication/ldap-ad/ldap-ad-authentication.properties" title="https://github.com/Alfresco/community-edition-old/blob/master/projects/repository/config/alfresco/subsystems/Authentication/ldap-ad/ldap-ad-authentication.properties" rel="nofollow noopener noreferrer"&gt;community-edition-old/ldap-ad-authentication.properties at master · Alfresco/community-edition-old · GitHub&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But is usual to see "&lt;SPAN style="color: #24292e; background-color: #ffffff;"&gt;sAMAccountName" as userIdAttributteName or ldap-ad in authentication chain, or&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #24292e; background-color: #ffffff;"&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #24292e; background-color: #ffffff;"&gt;--C.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Aug 2017 07:17:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35391#M14934</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-08-08T07:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35392#M14935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alfresco ldap (or ldap-ad) subsystem delegates authentication in AD, and so, no passwords are saved in Alfresco database. If you are right, Alfresco seems to do what it was made for. But if you are right, other aplications will be suitable of login issues during AD locks. And this would&amp;nbsp;be generated by&amp;nbsp;some application on your organization (Alfresco or another application) doing continuous wrong auth requests in AD, resulting in the corresponding temp locks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Aug 2017 07:28:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35392#M14935</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-08-08T07:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35393#M14936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To be more precise i will try to give you a detailed information of what we do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;situation 1:&lt;BR /&gt;- user account in ad is not locked -&amp;gt; user is able to login to alfresco (which is ok)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;situation 2:&lt;BR /&gt;- user tries to access a rest url, e.g. /alfresco/service/, user is prompted for username/password. if the user enters the wrong username/password for five times then the account is locked in ad&lt;BR /&gt;- user tries to login to alfresco -&amp;gt; user is not able to login, as the account ist locked in ad (as expected, the user is also unable to login through other applications that are chained to ad)&lt;BR /&gt;- account is unlocked in ad&lt;BR /&gt;- user tries to login to alfresco -&amp;gt; user ist not able to login (at the same time the user is able to login again through other applications that are chained to ad)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we believe, that the status of a user account is somewhere cached in alfresco, which prevents alfresco to do a authentication query towards ad where the user would already be unlocked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Aug 2017 07:42:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35393#M14936</guid>
      <dc:creator>t_schoeberl</dc:creator>
      <dc:date>2017-08-08T07:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35394#M14937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe it is related with this feature in&amp;nbsp;Alfresco 5.2:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.alfresco.com/docs/DOC-6301-alfresco-community-edition-52#jive_content_id_Slowdown_of_Brute_Force_Attacks__REPO1489" title="https://community.alfresco.com/docs/DOC-6301-alfresco-community-edition-52#jive_content_id_Slowdown_of_Brute_Force_Attacks__REPO1489" rel="nofollow noopener noreferrer"&gt;https://community.alfresco.com/docs/DOC-6301-alfresco-community-edition-52#jive_content_id_Slowdown_of_Brute_Force_Attac…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diving into repository.properties I see (you may check and confirm them also in System Information page in OOTB addon).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://svn.alfresco.com/repos/alfresco-open-mirror/alfresco/HEAD/root/projects/repository/config/alfresco/repository.properties" title="https://svn.alfresco.com/repos/alfresco-open-mirror/alfresco/HEAD/root/projects/repository/config/alfresco/repository.properties" rel="nofollow noopener noreferrer"&gt;https://svn.alfresco.com/repos/alfresco-open-mirror/alfresco/HEAD/root/projects/repository/config/alfresco/repository.pr…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;# Brute force protection&lt;BR /&gt;&lt;STRONG&gt;authentication.protection.enabled=true&lt;/STRONG&gt;&lt;BR /&gt;authentication.protection.limit=10&lt;BR /&gt;authentication.protection.periodSeconds=6&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Aug 2017 09:33:13 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35394#M14937</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-08-08T09:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35395#M14938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN class=""&gt;I have the same problem.&lt;/SPAN&gt; &lt;SPAN&gt;And it started to happen only after using version 5.2.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The problem is that some users have problems authenticating to AD, I realized that this usually happens after the user changes the AD password and especially when the user generates a password with special characters.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;I tried to identify if it could be the brute force attack feature but I did not find a relationship.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 11:07:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35395#M14938</guid>
      <dc:creator>robsoncardoso_t</dc:creator>
      <dc:date>2017-08-10T11:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35396#M14939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Solution:&lt;/P&gt;&lt;P&gt;In alfresco-global.properties&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;BR /&gt;authentication.protection.enabled=false&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now the user can log in after unlocking in ad.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But so we think that the mitigating brute force attack on user passwords in Alfresco does not work correctly.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://docs.alfresco.com/5.2/concepts/brute-force-passwords.html" title="http://docs.alfresco.com/5.2/concepts/brute-force-passwords.html" rel="nofollow noopener noreferrer"&gt;Mitigating brute force attack on user passwords | Alfresco Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 11:32:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35396#M14939</guid>
      <dc:creator>t_schoeberl</dc:creator>
      <dc:date>2017-08-10T11:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35397#M14940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN&gt;The protection mechanism should be better described.&lt;/SPAN&gt; &lt;SPAN class=""&gt;For that I understand only the user should be blocked after 10 unsuccessful login attempts (authentication.protection.limit = 10), but there are no reports of non-authenticating users attempting to log in with the wrong password several times.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 11:52:25 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35397#M14940</guid>
      <dc:creator>robsoncardoso_t</dc:creator>
      <dc:date>2017-08-10T11:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35398#M14941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this is not for using audit tools like hydra in an evil way. But I think it may be problematic for the final user, when Alfresco is configured with a complex authentication chain with several user directory origins, and the user is failing several times the real password because he/she&amp;nbsp;needs more coffee...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 12:49:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35398#M14941</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-08-10T12:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP Users cannot login</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35399#M14942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a similar problem and I think it has something to do with ldap-ad. When a user enters an incorrect password, their account gets locked on AD. When they are unlocked on AD, they are still locked on alfresco. The&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;authentication.protection.periodSeconds=6&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;settings seems to have no effect, as the account is locked until the alfresco service is restarted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution of :&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;authentication.protection.enabled=false&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;works for me too&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 22:15:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/some-ldap-users-cannot-login/m-p/35399#M14942</guid>
      <dc:creator>ainsof</dc:creator>
      <dc:date>2018-10-22T22:15:45Z</dc:date>
    </item>
  </channel>
</rss>

